首页> 外文会议>IEEE International Workshops on Enabling Technologies Infrastructure for Collaborative Enterprises >An evaluation of Java application containers according to security requirements
【24h】

An evaluation of Java application containers according to security requirements

机译:根据安全要求对Java应用程序集装箱进行评估

获取原文

摘要

Web browsers, Web servers, Java application servers and OSGi frameworks are all instances of Java execution environments that tun more or less untrusted Java applications. In all these environments, Java applications can come from different sources. Consequently, application developers rarely know which other applications exist in the target Java execution environment. This paper investigates the requirements that need to be imposed on such a container from a security point of view and how the requirements have been implemented by different Java application containers. More specifically, we show a general risk analysis considering assets, threats and vulnerabilities of a Java container. This risk analysis exposes generic Java security problems and leads to a set of security requirements. These security requirements are then used to evaluate the security architecture of existing Java containers for Java applications, applets, servlets, OSGi bundles, and Enterprise Java Beans. For comparison, the requirements are also examined for a C++ application.
机译:Web浏览器,Web服务器,Java应用程序服务器和OSGI框架是java执行环境的所有实例,这些环境或多或少不受信任的Java应用程序。在所有这些环境中,Java应用程序都可以来自不同的来源。因此,应用程序开发人员很少知道目标Java执行环境中存在哪些其他应用程序。本文调查了从安全的角度来看,需要对这种容器施加的要求以及如何由不同的Java应用程序集装箱实现的要求。更具体地说,我们考虑了java容器的资产,威胁和漏洞的一般风险分析。这种风险分析公布了通用Java安全问题,并导致了一系列安全要求。然后,这些安全要求将用于评估Java应用程序,小程序,Servlet,OSGi捆绑包和企业Java Bean的现有Java容器的安全架构。为了比较,还检查了C ++应用程序的要求。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号